News
-
Rail supplier portal breach reaches Stadler
A supplier platform incident at Stadler exposed technical data without affecting rail vehicles, production, personal data, or operational systems.
-
Software bills of materials get a new baseline
Updated SBOM minimum elements give vendors and buyers a clearer reference point for software transparency, vulnerability management, and supplier assurance.
-
Cyber sanctions widen across Europe
Eight European partner countries have aligned with EU cyber sanctions targeting individuals and entities linked to attacks against the Union and its partners.
-
Claude tests crossed into live systems
Anthropic says three cyber evaluation incidents allowed Claude models to reach the internet and access real production systems through a third-party test environment.
-
Product security gets an SME playbook
ENISA’s secure-by-design and secure-by-default playbook gives smaller manufacturers practical steps for building product security into engineering and release work.
-
AI agent rollout strains identity governance
Kocho says AI agents and non-human identities are expanding enterprise access faster than many organisations can govern, monitor, and hold accountable.
-
AI-discovered flaws show ordinary exploitation rates
VulnCheck says only 14 of 1,061 AI-assisted vulnerability discoveries were confirmed as exploited in the wild during the first half of 2026.
-
CNI supplier access emerges as repeated attack route
e2e-assure research says CNI organisations are experiencing repeated supplier compromise and credential theft, while many only review third party access after incidents.
-
North Korean campaign connects npm compromises
Amazon says compromises of axios, debug, chalk, and typo-crypto were linked to the same DPRK-linked actor, reframing separate incidents as a wider supply chain campaign.
-
Self-hosted Gitea platforms face RCE risk
Gitea has disclosed a critical remote code execution flaw that can let repository writers execute shell commands as the Gitea OS user.










